Fortinet FCSS_EFW_AD-7.6 Practice Test Questions and Exam Dumps Part12 Q221-240

View Full Fortinet FCSS_EFW_AD-7.6 Exam Dumps and Practice Test Dumps.

 

Question 221

Which FortiGate feature is used to define a preferred route for traffic based on its destination?

  1. Traffic shaping
  2. Policy-based routing
  3. Web Filter
  4. FortiView

Correct Answer: 2

Explanation

Policy-based routing allows FortiGate to make routing decisions using criteria beyond the normal destination-based routing table. Administrators can define policies that match characteristics such as source address, destination address, incoming interface, or other supported attributes and then specify the desired outgoing interface or gateway. This is useful when particular traffic needs to follow a different path than the standard routing decision. Policy-based routing should be configured carefully because its rules can change the expected path of selected traffic and affect connectivity or security.

Question 222

An administrator wants to prevent a user from accessing websites categorized as gambling. Which FortiGate security profile should be configured?

  1. IPS
  2. Antivirus
  3. Web Filter
  4. Traffic Shaping

Correct Answer: 3

Explanation

The Web Filter security profile can control access to websites according to URL categories and configured filtering policies. Administrators can use FortiGuard web-category information and local filtering settings to restrict categories such as gambling, malicious websites, or other unwanted content. The profile is then applied to an appropriate firewall policy so that matching web traffic is inspected. Web filtering may depend on traffic inspection and connectivity to required FortiGuard services. Administrators should verify category behavior and policy order when troubleshooting unexpected website access.

Question 223

Which security profile is primarily designed to detect and block known malicious files?

  1. Antivirus
  2. DNS Filter
  3. Application Control
  4. Local-in Policy

Correct Answer: 1

Explanation

The Antivirus security profile examines traffic for malicious files and known malware patterns. When applied to an appropriate firewall policy, it can inspect supported traffic and take configured actions when a threat is detected. Antivirus protection is different from IPS, which focuses more broadly on detecting and preventing network attacks and exploit patterns. Effective antivirus operation also depends on appropriate inspection settings and current security intelligence. Administrators should review logs when files are blocked to determine the detected threat and verify that the relevant firewall policy is handling the traffic.

Question 224

Which feature can control access to applications even when users access them through nonstandard ports?

  1. DNS Filter
  2. Application Control
  3. DHCP Server
  4. NTP

Correct Answer: 2

Explanation

Application Control can identify applications based on traffic characteristics rather than relying only on destination port numbers. This allows FortiGate to apply application-specific controls even when an application uses a nonstandard or unexpected port. Administrators can create application control profiles that allow, block, monitor, or otherwise handle selected applications according to the organization’s policy. Application identification may require suitable inspection and sufficient traffic information. This capability is useful when traditional service-based filtering cannot reliably identify the actual application generating network traffic.

Question 225

What is the primary purpose of a firewall policy on FortiGate?

  1. Store historical logs
  2. Assign administrator roles
  3. Determine how matching traffic is handled
  4. Synchronize system time

Correct Answer: 3

Explanation

A FortiGate firewall policy defines how traffic matching specified conditions should be handled. Conditions can include source and destination interfaces, addresses, users, services, schedules, and other supported criteria. The policy can permit or deny traffic and can also apply security profiles, logging, NAT, and related controls. Policies are evaluated according to their configured order, so an earlier matching policy can affect which rule handles traffic. Administrators should design policies carefully and regularly review unused, overly broad, or conflicting rules.

Question 226

Which routing protocol is commonly used to exchange routes between different autonomous systems?

  1. OSPF
  2. RIP
  3. BGP
  4. DHCP

Correct Answer: 3

Explanation

Border Gateway Protocol, or BGP, is designed to exchange routing information between autonomous systems. It is widely used for inter-domain routing and can also be deployed within large organizational networks where advanced routing control is required. BGP uses attributes and routing policies to influence route selection and advertisement. FortiGate can participate in BGP routing when configured appropriately. Administrators should carefully control which prefixes are advertised or accepted because incorrect BGP policies can cause unwanted route propagation or connectivity problems.

Question 227

Which OSPF component groups routers and helps limit the scope of link-state information?

  1. Areas
  2. VLANs
  3. Zones
  4. Address groups

Correct Answer: 1

Explanation

OSPF uses areas to organize the routing domain and limit the amount of link-state information that must be maintained throughout the network. Area 0 is the backbone area, and other areas can connect to it through appropriate OSPF routers. This hierarchical structure can improve scalability and reduce unnecessary routing information. FortiGate can participate in OSPF and exchange routes with neighboring routers. Correct interface configuration, network statements, areas, and neighbor relationships are important when troubleshooting OSPF route exchange.

Question 228

Which setting can restrict an administrator account so that it can connect only from approved IP addresses?

  1. Service group
  2. Trusted hosts
  3. IP pool
  4. SD-WAN rule

Correct Answer: 2

Explanation

Trusted hosts can restrict administrative access to FortiGate by specifying permitted source IP addresses or networks for an administrator account. This provides an additional security layer because valid credentials alone are not sufficient when the connection originates outside the configured trusted locations. Administrators can use trusted hosts to limit management access to dedicated management networks or approved workstations. The configured addresses should be maintained carefully because an incorrect trusted-host configuration can prevent legitimate administrators from accessing the device.

Question 229

A company wants to give a network administrator permission to view configuration settings but not change them. Which concept should be used?

  1. Role-based administrator profile
  2. Source NAT
  3. IPsec Phase 2
  4. Traffic selector

Correct Answer: 1

Explanation

A role-based administrator profile can provide restricted permissions to an administrator account. FortiGate administrator profiles allow organizations to define which areas an administrator can access and whether those areas are available with read-only or read-write permissions, depending on the configured profile. Providing view-only access is useful for monitoring or auditing personnel who do not need configuration privileges. This follows the principle of least privilege and reduces the possibility of accidental or unauthorized changes. Administrator permissions should be reviewed whenever a user’s responsibilities change.

Question 230

Which feature can prioritize or limit network traffic to manage available bandwidth?

  1. Web Filter
  2. Traffic shaping
  3. FortiToken
  4. DHCP

Correct Answer: 2

Explanation

Traffic shaping allows FortiGate to control how available bandwidth is allocated among network traffic. Administrators can configure shaping policies or profiles to limit bandwidth consumption or prioritize important traffic according to the network’s requirements. This can help prevent bandwidth-intensive applications from consuming resources needed by business-critical services. Traffic shaping should be planned around actual link capacity and application requirements. Monitoring traffic before and after configuration can help determine whether the configured limits or priorities are producing the intended network behavior.

Question 231

Which FortiGate feature provides graphical visibility into traffic, applications, and network activity?

  1. FortiView
  2. RADIUS
  3. VIP
  4. OSPF

Correct Answer: 1

Explanation

FortiView provides graphical and interactive visibility into various aspects of FortiGate activity, including traffic, applications, sources, destinations, and security-related information. Administrators can use FortiView to identify traffic patterns, investigate unusual activity, and obtain a quick operational view of the firewall. It is primarily a visibility and analysis feature rather than a replacement for firewall policies or security profiles. More detailed historical analysis and reporting may require other Fortinet components, depending on the deployment and logging architecture.

Question 232

Which Fortinet product is designed primarily for centralized log analysis, reporting, and security event visibility?

  1. FortiManager
  2. FortiAuthenticator
  3. FortiAnalyzer
  4. FortiWeb

Correct Answer: 3

Explanation

FortiAnalyzer is designed for centralized collection, analysis, reporting, and management of logs from supported Fortinet devices and services. It can help security teams investigate events, identify trends, and generate reports from centralized data. This differs from FortiManager, which primarily focuses on centralized device and configuration management. FortiAnalyzer is especially useful when administrators need historical visibility that extends beyond what can conveniently be reviewed directly on an individual FortiGate. Proper logging configuration and storage planning are important for effective analysis.

Question 233

Which Fortinet product provides centralized identity and authentication services for network access?

  1. FortiAuthenticator
  2. FortiAnalyzer
  3. FortiView
  4. FortiManager

Correct Answer: 1

Explanation

FortiAuthenticator provides centralized identity and authentication capabilities within Fortinet environments. It can support authentication services and integrate with identity sources, helping organizations centralize user authentication rather than configuring every network device independently. It can also support functions associated with Fortinet authentication architectures and token-based authentication. When deployed with FortiGate, administrators must configure appropriate communication, authentication methods, and identity integration. Centralized authentication can simplify account management while providing a consistent foundation for access-control policies across the network.

Question 234

Which Fortinet product is specifically designed to protect web applications from attacks?

  1. FortiEDR
  2. FortiWeb
  3. FortiManager
  4. FortiToken

Correct Answer: 2

Explanation

FortiWeb is Fortinet’s web application firewall platform, designed to protect web applications from application-layer attacks and malicious HTTP or HTTPS requests. It can inspect web traffic and apply security controls designed specifically for web applications. FortiWeb differs from FortiGate because FortiGate primarily provides network security and firewall functions, while FortiWeb focuses on protecting web applications. Deployments should place the appropriate protection layer in the traffic path and configure policies according to the application’s architecture and legitimate request patterns.

Question 235

Which feature can restrict administrative access to specific management services such as HTTPS or SSH?

  1. Administrative access settings
  2. Application Control
  3. IPsec traffic selectors
  4. Traffic shaping

Correct Answer: 1

Explanation

Administrative access settings determine which management services are available on FortiGate interfaces. Depending on the configuration, administrators can permit services such as HTTPS, SSH, ping, or other supported management functions on selected interfaces. Limiting management services reduces the number of exposed administrative entry points. For example, an organization may permit HTTPS and SSH only on a dedicated management interface while disabling unnecessary access on user-facing interfaces. These settings should be combined with strong authentication, trusted hosts, and appropriate administrator permissions.

Question 236

Which protocol is used by network devices to synchronize their clocks with a time source?

  1. DNS
  2. DHCP
  3. NTP
  4. LDAP

Correct Answer: 3

Explanation

Network Time Protocol, or NTP, synchronizes the system clock of network devices with an authoritative or configured time source. Accurate time is important for security logging, event correlation, authentication mechanisms, certificates, and troubleshooting. FortiGate can use configured NTP servers to maintain consistent system time. If device clocks differ significantly, timestamps in logs from different systems may be difficult to correlate. Administrators should configure reliable time sources and verify that the FortiGate can communicate with them through the required network path.

Question 237

Which FortiGate function can automatically provide IP addresses and related network parameters to clients?

  1. DHCP server
  2. BGP
  3. VIP
  4. Web Filter

Correct Answer: 1

Explanation

A DHCP server automatically provides clients with network configuration information such as IP addresses, subnet masks, default gateways, and DNS server information. FortiGate can operate as a DHCP server on suitable interfaces, reducing the need for a separate DHCP service in smaller or specific network segments. Administrators can configure address ranges and lease parameters according to network requirements. DHCP configuration should avoid overlapping address ranges with static assignments or another DHCP server, because conflicting address allocation can create connectivity problems.

Question 238

What does source NAT typically accomplish for outbound private network traffic?

  1. Changes the destination port
  2. Converts a private source address to a translated address
  3. Creates an OSPF area
  4. Encrypts the traffic

Correct Answer: 2

Explanation

Source NAT changes the source address of outgoing traffic as it passes through FortiGate. A common use is translating private internal addresses to a public address so that internal clients can access external networks. FortiGate can perform source NAT using the outgoing interface address or other supported translation mechanisms, depending on policy configuration. Source NAT does not provide encryption; VPN technologies are used when confidentiality is required. Administrators should also consider return traffic, routing, and available translated addresses when troubleshooting NAT behavior.

Question 239

Which security feature can detect known network attack patterns and take configured preventive action?

  1. IPS
  2. NTP
  3. DHCP
  4. Address group

Correct Answer: 1

Explanation

The Intrusion Prevention System, or IPS, examines network traffic for patterns associated with known attacks, exploits, and other suspicious behavior. FortiGate IPS uses signatures and related detection mechanisms to identify potentially malicious traffic and can take actions such as blocking or logging according to the configured profile. IPS differs from Antivirus, which primarily focuses on malicious files and malware detection. Administrators should keep security intelligence current and tune IPS settings appropriately to balance protection with legitimate application traffic and minimize unnecessary false positives.

Question 240

A firewall policy permits traffic, but the connection still fails because FortiGate has no valid route to the destination. Which area should be investigated first?

  1. Web Filter
  2. Administrator profiles
  3. Routing
  4. FortiToken

Correct Answer: 3

Explanation

Routing should be investigated when FortiGate does not have a valid path to the destination. A firewall policy can permit traffic, but policy permission alone does not create a route. Administrators should examine the routing table and verify that an appropriate route, gateway, or interface exists for the destination. They should also check route preference and any policy-based routing that may influence the forwarding decision. Once routing is confirmed, firewall policy matching, NAT, and security profiles can be investigated if the connection still fails.